Manav.id
Vertical · 5 min read

Proofed once at registration, stolen at the dock: the 2026 cargo theft arithmetic

Proofed once at registration, stolen at the dock: the 2026 cargo theft arithmetic

Two numbers from 2026 sit awkwardly together. Cargo theft incidents fell twenty-six percent year over year. Losses more than doubled, to $304.6 million in a single quarter. Fewer thefts, bigger losses — and the explanation is that the industry hardened the front door while the money walks out of the loading dock.

Why did cargo thefts fall while losses more than doubled?

Because the control moved to registration and the attack moved to the dock. FMCSA began requiring photo ID and a live selfie for operating authority in January 2026 and retired MC numbers. Fewer, better-targeted thefts of higher-value loads is what you get when you proof once and never again.

Key takeaways
  • FMCSA identity proofing took effect in January 2026: government photo ID and a live facial selfie to obtain operating authority. It addresses registration, which is not where the losses occur.
  • The FBI's IC3 reported 2025 cargo theft losses of approximately $725 million, a 60% increase, driven by cyber-enabled strategic theft.
  • Across eleven lifecycle moments from registration to delivery, nine inherit identity rather than establish it. Three deserve a cryptographic re-proof.

What changed in registration, and when

Operating authority grantedphoto ID, live selfiehardenedMonths passidentity not re-checkedgapCarrier identity assumedor account compromisedLoad collectedat the dockno re-proofing
Registration hardened. Nothing re-establishes identity at the moment freight changes hands.

In January 2026 the Federal Motor Carrier Safety Administration implemented identity proofing for new carrier and broker applications, requiring a government-issued photo identification and a live facial selfie. MC numbers were retired in the same period, consolidating identification on the USDOT number. In May 2026 a modernised registration system launched, described by the Department as improving fraud detection and data quality.

These are substantive changes and they were correctly motivated. Registration fraud — obtaining authority under a fabricated or stolen identity — was a real and growing problem, and the controls address it directly.

What the loss data did in the same period

The FBI's Internet Crime Complaint Center issued a public service announcement on 30 April 2026 on cyber-enabled strategic cargo theft, reporting that estimated 2025 losses in the United States and Canada reached approximately $725 million — roughly a 60% increase over 2024.

Industry data through 2026 continued the pattern. Reported incidents in the second quarter fell about 26% year over year, while estimated losses in that quarter reached $304.6 million against $135.7 million a year earlier. Earlier in the year, more than 1,120 incidents with roughly $121 million in losses were recorded across the first five months.

The divergence. Incident counts and loss totals moving in opposite directions is the signature of a shift in method, not in volume.
MetricDirection in 2026Implication
Incident countDown ~26% year over yearFewer, more selective operations
Loss totalMore than doubledHigher value per incident
Implied value per incidentUp sharplyTargets are being selected, not encountered
MethodShift toward strategic and cyber-enabled theftIdentity, not force

Why hardening registration does not move those numbers

Strategic cargo theft does not begin with obtaining authority. It begins with impersonating authority that already exists — a legitimate carrier's USDOT number, a real insurance certificate, a plausible email domain, a dispatcher who answers the phone.

Identity proofing at registration raises the cost of creating a new fraudulent carrier. It does nothing about presenting the credentials of an existing legitimate one, which is both cheaper and more effective because the attributes survive every downstream check.

A check performed once, years ago, against a person who is not the one standing at your dock, is not a check.

The Freight Identity Lifecycle Map

Eleven moments between registration and delivery. For each, whether identity is established (proven at that moment), inherited (carried forward from an earlier proof), or asserted (claimed with no verification).

#MomentIdentity stateLoss concentration
1Operating authority registrationEstablishedLow
2Load board posting and searchAssertedLow
3Carrier onboarding by brokerInherited (attributes checked)Moderate
4Rate confirmation issuedAssertedModerate
5Re-tender to another carrierAssertedHigh
6Driver assignmentAssertedModerate
7Arrival and gate check-inAssertedHigh
8Dock release of freightAssertedHighest
9In-transit status updatesAssertedLow
10Delivery and proof of deliveryAssertedModerate
11Settlement and paymentInheritedModerate

Nine of eleven inherit or assert. The three carrying the highest loss concentration — re-tender, gate check-in and dock release — are all pure assertion, verified by document inspection.

The three moments worth a cryptographic re-proof

  1. Re-tender (moment 5). Express permitted co-brokerage as a delegation with an explicit depth limit, so an unauthorised re-tender is detectable rather than discoverable at claim time.
  2. Gate check-in (moment 7). The driver presents a signed assertion under a load-bound delegation, not a rate confirmation PDF.
  3. Dock release (moment 8). The shipper verifies the assertion offline against a published key before releasing freight.

Each is a single point in an existing workflow. None requires a new system in the freight path, and all three verify without connectivity — which matters at a dock in an industrial park.

Reading the numbers carefully

Incident counts and loss totals differ between IC3, industry databases and insurer datasets because inclusion criteria differ — some count attempts, some count only confirmed thefts, some include in-transit pilferage. This article cites each source with its own figure rather than selecting the largest, and the per-incident implied value used above derives from the quarterly industry data cited, not from a national average.

What none of the datasets disagrees about is the direction: value per incident is rising sharply, and the method producing that rise is identity-based.

What the two numbers together mean

A falling count with rising losses is the signature of a control that raised the cost of entry. Casual thieves were priced out; the ones who remain target fewer, larger loads and invest more per attempt. That is a real improvement in one dimension and a worsening in another, and reporting either number alone misleads.

Where the lifecycle has gates
StageGate today
RegistrationStrong, since January 2026
Account accessPassword and sometimes MFA
Load acceptanceNone — a tender in a system
PickupPaperwork

Objections and honest limits

“So registration hardening failed.” It did not. It removed a class of attacker, which is what the falling count shows. It simply cannot reach the dock, which is where the remaining loss concentrates.

“Identity re-proofing at every pickup is impractical.” It is. Re-proofing is not the same as re-authorising — a signature bound to this tender takes seconds and does not re-run identity verification.

Closing the lifecycle gap

  1. Treat registration and pickup as separate gates. They answer different questions.
  2. Bind the tender to a credential at acceptance. When the carrier takes the load, not at the dock.
  3. Verify that binding at pickup. Seconds, fail closed.
  4. Re-affirm carrier identity periodically. Not per load — per quarter is enough to catch account takeover.

Terms used here

Operating authority
The federal grant permitting a carrier to operate, now subject to photo ID and live selfie proofing.
Double brokering
Re-tendering a load to another carrier without authority, which breaks the chain of custody and insurance.
Strategic theft
Theft using assumed identity and documentation rather than force — the category that grew.

Frequently asked questions

Did FMCSA's changes make things worse? No. They addressed registration fraud, which was a genuine problem. The point is that the losses concentrate elsewhere in the lifecycle, so improvement at registration was never going to move the loss numbers.

Is this just fictitious pickup? Fictitious pickup is the dominant technique at moment 8. Moments 5 and 7 involve related but distinct methods — unauthorised re-tender and driver impersonation — which is why they are separated.

What does a dock actually do differently? It stops evaluating documents and starts verifying a signature against a published key. The verification is offline and takes under a second.

Does this require every carrier to adopt something? For a given lane, it requires the broker and the shipper to agree and the carrier's driver to hold a credential. It works bilaterally before it works industry-wide.

Why did losses rise while thefts fell? Registration hardening priced out casual thieves. Those remaining target fewer, higher-value loads and invest more per attempt.

Is re-proofing needed at every pickup? No. Re-authorising is not re-proofing. A signature bound to this tender takes seconds and does not repeat identity verification.

Where is the remaining gap? Between load acceptance and pickup, where nothing re-establishes that the collector is the carrier that accepted.

Where this fits in Manav

Manav binds the authorising person to the exact release, tender or instruction, and produces a receipt a shipper, a terminal or a broker can verify at the gate without a phone call.

See release receipts →

Sources and further reading